Home
MEDIUM: 6.7 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HHIGH: 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Ver.1.0.1 to Ver.1.1.4
affected
Ver.2.0.0 to Ver.2.0.2
affected
Ver.1.0.0 to Ver.1.1.4
affected
Description
SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Problem types
Unquoted search path or element
Product status
Ver.1.0.0 to Ver.1.1.4
References
products.sanyodenki.com/...a/document/sanups/H0033449_en.pdf
products.sanyodenki.com/...a/document/sanups/H0033413_jp.pdf